[clamav-users] More fp's.

Sierk Bornemann sierkb at gmx.de
Mon Dec 26 12:39:52 UTC 2016


$ sw_vers
ProductName:	Mac OS X
ProductVersion:	10.12.2
BuildVersion:	16C67


$ cat /Users/$USER/Library/Logs/ClamXavSentry-scan.log | grep FOUND

/Applications/Firefox.app/Contents/Resources/omni.ja: Win.Trojan.Toa-5370166-0 FOUND
/Applications/Firefox.app/Contents/Resources/browser/omni.ja: Win.Trojan.Toa-5370261-0 FOUND
/Applications/Firefox.app/Contents/Resources/omni.ja: Win.Trojan.Toa-5370166-0 FOUND
/Applications/Firefox.app/Contents/Resources/browser/omni.ja: Win.Trojan.Toa-5370261-0 FOUND
/Users/$USER/Library/Caches/Firefox/Profiles/qvmrp8ae.default/startupCache/startupCache.8.little: Win.Trojan.Toa-5370166-0 FOUND
/Users/$USER/Library/Caches/Firefox/Profiles/qvmrp8ae.default/startupCache/startupCache.8.little: Win.Trojan.Toa-5370166-0 FOUND
/Users/$USER/Library/Caches/Firefox/Profiles/qvmrp8ae.default/startupCache/startupCache.8.little: Win.Trojan.Toa-5370166-0 FOUND
/Users/$USER/Library/Application Support/Firefox/Profiles/qvmrp8ae.default/extensions/uBlock0 at raymondhill.net.xpi: Win.Trojan.Toa-5370166-0 FOUND
/Users/$USER/Library/Caches/Firefox/Profiles/qvmrp8ae.default/cache2/entries/0BBADECE8C7B469B3A6EE6C185C5E0D044A6E376: Win.Trojan.Toa-5370166-0 FOUND
/Users/$USER/Library/Caches/Firefox/Profiles/qvmrp8ae.default/cache2/entries/0BBADECE8C7B469B3A6EE6C185C5E0D044A6E376: Win.Trojan.Toa-5370166-0 FOUND
/Users/$USER/Library/Caches/Firefox/Profiles/qvmrp8ae.default/startupCache/startupCache.8.little: Win.Trojan.Toa-5370166-0 FOUND
/Users/$USER/Library/Caches/Firefox/Profiles/qvmrp8ae.default/startupCache/startupCache.8.little: Win.Trojan.Toa-5370166-0 FOUND

False Positives for:

Firefox.app…  /Resources/…
Firefox.app … /Caches/… startupCache.8.little
Firefox.app … /Caches/…0BBADECE8C7B469B3A6EE6C185C5E0D044A6E376
Firefox.app … /extensions/…uBlock0 at raymondhill.net.xpi

Possible cause: signature relating
Win.Trojan.Toa-5370166-0
Win.Trojan.Toa-5370261-0


Please fix!


Merry Christmas,
Sierk Bornemann





More information about the clamav-users mailing list